300-710 — Frequently Asked Questions

Community-vetted answers to 17 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

How Do You Isolate BVI Traffic on a Routed FTD?

An IP address on the BVI is mandatory for it to pass traffic, but that address is what makes the BVI routable. Without a separate VRF, traffic can still be forwarded to other interfaces via the global routing table.

No. Physical interfaces that are members of a bridge group are Layer 2 ports and do not hold IP addresses, so there is nothing to remove. Routing is decided at the BVI, which is why the VRF approach is used.

How Do You Segment Department Traffic Across an Active FTD HA Pair?

Active/standby keeps only one chassis forwarding at a time, so it fails the requirement that both firewalls pass traffic and provides no separate logical firewall per department.

No; subinterfaces can separate traffic on one FTD, but the scenario needs independent firewall instances so each department's policy and forwarding domain are isolated.

What Do Low-Impact Attacks in the Firepower Risk Report Indicate?

FMC logs every triggered intrusion rule, then downgrades the impact level when the network map shows the target host lacks the vulnerable OS, service, or port the rule targets.

No. It means FMC sees no vulnerable target for that signature; if discovery later reveals the host as vulnerable, the impact level can change.

How Do You Validate TID Feeds Are Downloaded and Used?

The Advanced Settings checkbox only shows TID is enabled on that policy. It does not confirm the new sources downloaded indicators or that they were published to the Threat Defense devices.

On the Threat Intelligence Director Sources page, the source status indicator and indicator count show whether each configured feed was retrieved successfully and whether it has been published to sensors.

Which Policy Is Associated With an Access Control Policy for Malware Defense?

File policies are attached to access control rules that allow traffic, not to the access control policy itself, and they cannot decrypt TLS. The question asks what is associated with the access control policy.

Yes. Decryption exposes the files, but the Allow rule must still reference a file policy with Malware Cloud Lookup and Block Malware so the files are actually inspected and blocked.

Why Can't Users Reach a Cloud Web Server After Access Control Changes?

It bypasses the validation step and may override URL filtering or other policy intent; connection events show which rule or category actually blocked the traffic before you change the policy.

Packet capture can confirm a block, but setting a rule to monitor only logs traffic and does not represent a targeted fix; option B's connection-event review is the proper troubleshooting step.

How to Identify All UDP Ports in a Firepower Port Object?

In FMC port objects, the port field is mandatory for TCP/UDP; you must enter 1–65535 to cover all ports, as confirmed by official documentation.

A port object matches TCP/UDP ports, while an IP protocol object (option D) matches the IP protocol number (e.g., 17 for UDP) but cannot specify individual ports.

Which FTD Mode Survives Any Failure at the Perimeter?

Snort fail open only passes traffic when the Snort process fails; it does not protect against power loss or hardware failure, which hardware bypass is designed to cover.

Passive mode avoids inline failure by receiving a SPAN, RSPAN, or ERSPAN copy, but it cannot block traffic inline, so it does not satisfy the IPS-at-the-perimeter premise.

Cisco documents hardware bypass for certain interface modules on Firepower 9300, 4100, and 2100 series appliances, so verify platform support before relying on it.

← Back to 300-710 Securing Networks with Cisco Firepower Study Guide